<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MediaBundle (&lt; 7.3.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mediabundle--7.3.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:53:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mediabundle--7.3.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Kunstmaan MediaBundle Blacklist Bypass Leading to Remote Code Execution</title><link>https://feed.craftedsignal.io/briefs/2026-10-kunstmaan-cms-rce/</link><pubDate>Wed, 07 Oct 2026 22:53:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-kunstmaan-cms-rce/</guid><description>An authentication-required blacklist bypass vulnerability in the Kunstmaan MediaBundle allows malicious administrators to upload arbitrary executable files via case-sensitive extension filtering, resulting in remote code execution.</description><content:encoded><![CDATA[<p>Kunstmaan MediaBundle versions prior to 7.3.2 are vulnerable to a remote code execution (RCE) flaw due to improper handling of uploaded file extensions. The application employs a blacklist to prevent the upload of dangerous file types (e.g., .php, .htaccess); however, the validation logic performs a case-sensitive check before the file extension is normalized to lowercase. An attacker with authenticated administrator access to the media management section can bypass this filter by uploading a file with mixed-case extensions (e.g., .pHp).</p>
<p>The vulnerability is further exacerbated by an incomplete default blacklist that fails to cover common executable extensions such as .phtml, .php5, .phar, .shtml, and .cgi, as well as insecure regex interpolation. Once uploaded, these files are saved to a web-accessible directory and can be executed by the web server. This vulnerability, tracked as CVE-2026-104890, necessitates an immediate upgrade to version 7.3.2 or higher, along with an audit of existing upload directories for previously stored malicious files.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains authentication as a user with administrative access to the media management section of the Kunstmaan CMS.</li>
<li>Attacker crafts a malicious payload file with an unconventional casing for an executable extension (e.g., <code>shell.pHp</code>).</li>
<li>Attacker submits the file via the MediaBundle upload interface.</li>
<li>The application performs a case-sensitive regex check against the blacklist, which fails to flag the mixed-case extension.</li>
<li>The application normalizes the filename to lowercase, inadvertently turning the file into a valid executable format (e.g., <code>shell.php</code>) on the filesystem.</li>
<li>The web server processes the uploaded file from the web-accessible directory.</li>
<li>The attacker executes the file over HTTP, resulting in remote code execution under the privileges of the web server process.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation grants an authenticated administrator arbitrary code execution on the underlying host. This allows for full system compromise, data exfiltration, or lateral movement within the environment. Because the vulnerability requires administrative access, the primary risk is from compromised accounts or malicious insiders.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the kunstmaan/media-bundle and kunstmaan/bundles-cms packages to version 7.3.2 or later immediately to address CVE-2026-104890.</li>
<li>Audit the web-accessible media upload directory for existing files containing executable extensions (.php, .phtml, .php5, .phar, .shtml, .cgi) to identify potential prior exploitation.</li>
<li>Implement web server-level restrictions (e.g., disabling PHP execution in the upload directory) as a compensating control if immediate patching is not possible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>